Thank you for sending your enquiry! One of our team members will contact you shortly.
Thank you for sending your booking! One of our team members will contact you shortly.
Duration 21 hours
Course Outline
1. The Scope and Concepts of Static Code Analysis
- Definitions: static analysis, SAST, rule categories, and severity levels
- The role of static analysis in a secure SDLC and risk coverage
- How SonarQube aligns with security controls and developer workflows
2. SonarQube Overview: Architecture and Features
- Essential services, database, and scanner components
- Best practices for Quality Gates, Quality Profiles, and gate configurations
- Security-focused features: vulnerabilities, SAST rules, and CWE mapping
3. Navigating the SonarQube Server Interface
- Tour of the server UI: projects, issues, rules, metrics, and governance views
- Analyzing issue pages, traceability, and remediation advice
- Generating and exporting reports
4. Configuring SonarScanner with Build Tools
- Setting up SonarScanner for Maven, Gradle, Ant, and MSBuild
- Best practices for scanner properties, exclusions, and multi-module projects
- Creating necessary test data and coverage reports for precise analysis
5. Azure DevOps Integration
- Establishing SonarQube service connections in Azure DevOps
- Including SonarQube tasks in Azure Pipelines and adding PR decorations
- Importing Azure Repos into SonarQube to automate analyses
6. Project Configuration and Third-Party Analyzers
- Setting project-level Quality Profiles and selecting rules for Java and Angular
- Utilizing third-party analyzers and managing the plugin lifecycle
- Defining analysis parameters and understanding parameter inheritance
7. Roles, Responsibilities, and Secure Development Methodology Review
- Role separation: developers, reviewers, DevOps, and security owners
- Creating a roles and responsibilities matrix for CI/CD processes
- Reviewing and recommending improvements to existing secure development methodologies
8. Advanced Topics: Adding Rules, Tuning, and Enhancing Global Security
- Using the SonarQube Web API to create and manage custom rules
- Modifying Quality Gates and enforcing automated policies
- Strengthening SonarQube server security and access control practices
9. Hands-on Lab Sessions (Practical Application)
- Lab A: Set up SonarScanner for five Java repositories (using Quarkus where relevant) and review results
- Lab B: Configure Sonar analysis for one Angular front-end and interpret findings
- Lab C: Comprehensive pipeline lab—integrate SonarQube with an Azure DevOps pipeline and enable PR decoration
10. Testing, Troubleshooting, and Report Interpretation
- Strategies for generating test data and measuring coverage
- Addressing common scanner, pipeline, and permission issues
- Presenting SonarQube reports to both technical and non-technical stakeholders
11. Best Practices and Recommendations
- Selecting rule sets and strategies for incremental enforcement
- Workflow suggestions for developers, reviewers, and build pipelines
- A roadmap for scaling SonarQube in enterprise settings
Summary and Next Steps
Requirements
- Knowledge of the software development lifecycle
- Experience with source control and fundamental CI/CD concepts
- Familiarity with Java or Angular development environments
Target Audience
- Developers (Java / Quarkus / Angular)
- DevOps and CI/CD engineers
- Security engineers and application security reviewers
Testimonials (1)
Engaging, and hands on practise.